Circuit Wire — a daily news update from On The Circuit.
CISA and six partner agencies updated a joint advisory on Tuesday, July 22, warning that Iranian-affiliated hackers are disrupting industrial control devices across US water, energy, and government facilities. The revised advisory names controllers made by Rockwell Automation, Schneider Electric, and Siemens as targets, a wider list than the version put out in the spring.
The Cybersecurity and Infrastructure Security Agency issued the alert alongside the FBI, the National Security Agency, the Environmental Protection Agency, the Department of Energy, US Cyber Command, and the Treasury Department. The agencies first published the advisory on April 7 and revised it after tracking further intrusions into US systems.
Programmable logic controllers, known as PLCs, are the small computers that run pumps, valves, and other machinery at plants and utilities. The advisory says the attackers reach these devices through internet-connected operational technology and configuration software. Once inside, they change settings, copy the project files that describe how a facility runs, and alter the displays that operators watch.
Affected sectors include Water and Wastewater Systems, Energy, and Government Services and Facilities, down to local municipalities. The advisory does not tie the intrusions to a single named group, describing the attackers as Iranian-affiliated advanced persistent threat actors. Some victims reported operational disruption and financial loss, according to a summary of the update published by Manufacturing Business Technology.
The revised advisory adds technical detail on how the actors pull files off devices and which ports and models they favor. It also lists new steps for defenders, including securing cellular modems, separating control networks, validating project files, and watching for malicious changes in reusable blocks of code. The agencies published fresh tables of internet addresses tied to the activity.
The warning follows a run of Iranian-linked activity against US operational technology. Agencies issued an advisory in 2023 on IRGC-affiliated actors exploiting PLCs at water and wastewater plants. Water and energy operators have faced repeated attempts to reach exposed control systems since then.
The update lands during open conflict between the United States, Israel, and Iran, with repeated warnings that Iran and its allies could hit US targets. The advisory urges operators to restrict direct internet access to control devices and to apply its updated mitigations.
Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.
Spotted something we should cover? Send tips and feedback via circuit-magazine.com.

